<a id="audit-option-filter" />

**`filter (string : "")`** <EnterpriseAlert inline="true" />

Only write audit log entries matching the provided
[filtering expression](/vault/docs/enterprise/audit/filtering) to the audit
device.

**Example**: `filter='mount_type == "kv-v2"'`

